← Vulnerability feed

Vulnerability record · CVE-2018-21226 · published 28 April 2020

CVE-2018-21226: Netgear jnr1010 firmware improper privilege management vulnerability

Netgear · Jnr1010 Firmware

Certain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before 1.1.0.48, WNR1000v4 before 1.1.0.48, WNR2020 before 1.1.0.48, and WNR2050 before 1.1.0.48.

8.8 CVSS 3.1 High EPSS 0.70% · top 48.7% CWE-269 · Improper privilege management
8.8CVSS 3.1 base score, v2 5.8
0.70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Certain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before 1.1.0.48, WNR1000v4 before 1.1.0.48, WNR2020 before 1.1.0.48, and WNR2050 before 1.1.0.48.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-21226 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10174NETGEAR router buffer overflow in hidden_lang_avi parameterThe NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. An unauth…KEVEPSS 83%analysed9.8CVE-2020-35799Netgear d3600 firmware out-of-bounds write vulnerabilityCertain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 befor…EPSS 1.2%9.8CVE-2020-26927Netgear ac2100 firmware vulnerabilityCertain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.42, R60…EPSS 1.1%9.8CVE-2020-26908Netgear d6200 firmware vulnerabilityCertain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74, PR2000 before 1.0.0.30, R6…EPSS 2.1%9.8CVE-2019-20488Netgear wnr1000 firmware os command injection vulnerabilityAn issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to com…EPSS 2.1%9.8CVE-2019-20489Netgear wnr1000 firmware improper authentication vulnerabilityAn issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other proble…EPSS 1.3%9.8CVE-2013-3316Netgear wnr1000 firmware improper authentication vulnerabilityNetgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".EPSS 4.8%9.8CVE-2013-3317Netgear wnr1000 firmware improper authentication vulnerabilityNetgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.EPSS 4.8%

Source: NIST National Vulnerability Database (record CVE-2018-21226), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.